Skip to main content

Microsoft Releases October 2022 Security Updates

Scheduled updates for Microsoft products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products


The following platforms are also known to be affected:

  • Active Directory Domain Services
  • Azure
  • Azure Arc
  • Client Server Run-time Subsystem (CSRSS)
  • Microsoft Graphics Component
  • Microsoft WDAC OLE DB provider for SQL
  • NuGet Client
  • Remote Access Service Point-to-Point Tunneling Protocol
  • Role: Windows Hyper-V
  • Service Fabric
  • Visual Studio Code
  • Windows Active Directory Certificate Services
  • Windows ALPC
  • Windows CD-ROM Driver
  • Windows COM+ Event System Service
  • Windows Connected User Experiences and Telemetry
  • Windows CryptoAPI
  • Windows DHCP Client
  • Windows Distributed File System (DFS)
  • Windows DWM Core Library
  • Windows Event Logging Service
  • Windows Group Policy
  • Windows Group Policy Preference Client
  • Windows Internet Key Exchange (IKE) Protocol
  • Windows Kernel
  • Windows Local Security Authority (LSA)
  • Windows Local Security Authority Subsystem Service (LSASS)
  • Windows Local Session Manager (LSM)
  • Windows NTFS
  • Windows NTLM
  • Windows ODBC Driver
  • Windows Perception Simulation Service
  • Windows Point-to-Point Tunneling Protocol
  • Windows Portable Device Enumerator Service
  • Windows Print Spooler Components
  • Windows Resilient File System (ReFS)
  • Windows Secure Channel
  • Windows Security Support Provider Interface
  • Windows Server Remotely Accessible Registry Keys
  • Windows Server Service
  • Windows Storage
  • Windows TCP/IP
  • Windows USB Serial Driver
  • Windows Web Account Manager
  • Windows Win32K
  • Windows WLAN Service
  • Windows Workstation Service

Threat details

Introduction

Microsoft has released updates to address 84 vulnerabilities in Microsoft products, with 15 of them rated as critical. An unauthenticated, remote attacker could exploit some of these vulnerabilities to take control of an affected system.

Exploitation in the wild

Microsoft have reported exploitation of the Windows COM+ Event System Service Elevation of Privilege vulnerability, known as CVE-2022-41033, and CISA has added it to their Known Exploited Vulnerabilities Catalog.

A proof-of-concept has been released for a critical Windows CryptoAPI spoofing bug known as CVE-2022-34689. The vulnerability was originally discovered by the US National Security Agency (NSA) and National Cyber Security Centre (NCSC). Affected organisations are encouraged to read Microsoft's guidance for these vulnerabilities and apply any relevant updates. 


Threat updates

Date Update
26 Jan 2023 Proof-of-concept released for a critical Windows CryptoAPI spoofing bug

This article has been updated to reflect the status of exploitation of CVE-2022-34689.

21 Oct 2022 Microsoft issues Out-of-Band (OOB) advisory for SSL/TLS handshake fail

Microsoft has reported that after installing KB5018421, some types of SSL (Secure Sockets Layer) and TLS (Transport Layer Security) connections might have handshake failures. 

Affected organisation should review Window Release Health message for their relevant system:

  • Cumulative updates:
    • Windows 11, version 21H2: KB5020387
    • Windows Server 2022: KB5020436
    • Windows 10, version 20H2; Windows 10, version 21H1; Windows 10, version 22H1; Windows 10 Enterprise LTSC 2021: KB5020435
    • Windows 10 Enterprise LTSC 2019; Windows Server 2019: KB5020438
    • Windows 10 2016 LTSB; Windows Server 2016: KB5020439
    • Windows 10 2015 LTSB; KB5020440
  • Standalone Updates:
    • Windows 8.1; Windows Server 2012 R2: KB5020447
    • Windows Server 2012: KB5020449
    • Windows 7 SP1; Windows Server 2008 R2 SP1: KB5020448

Remediation advice

Affected organisations are encouraged to review Microsoft’s October 2022 Security Update Summary and Deployment Information and apply the relevant updates.



Last edited: 26 January 2023 2:32 pm